CVE-2017-11570: High severity FontForge FontForge vulnerability
Published Jul 23, 2017
·Updated
FontForge 20161012 is vulnerable to a buffer over-read in umodenc (parsettf.c) resulting in DoS or code execution via a crafted otf file.
Affected Software
1 affected component
FontForge FontForge=20161012
Remediation
Patch Available
Event History
Jul 23, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-11570?
CVE-2017-11570 has been classified as a high severity vulnerability due to its potential for causing denial of service or code execution.
2
How do I fix CVE-2017-11570?
To remediate CVE-2017-11570, updating to a patched version of FontForge that addresses the buffer over-read is recommended.
3
What is the impact of CVE-2017-11570?
The impact of CVE-2017-11570 includes the possibility of denial-of-service attacks or unauthorized code execution when processing a malicious OTF file.
4
Which versions of FontForge are affected by CVE-2017-11570?
CVE-2017-11570 specifically affects FontForge version 20161012.
5
What type of vulnerability is CVE-2017-11570?
CVE-2017-11570 is categorized as a buffer over-read vulnerability located in the umodenc function of parsettf.c.